• Product
  • Who We Help
    • Sales & RevOps
    • Support & CX
    • Marketing
    • Executives
    • Operations
  • Client Services
  • Company
    • About
    • Careers
    • Blog
    • Security & Privacy
    • Partners
    • Contact Us
    • FAQs
  • Case Studies
harpin.AI harpin.AI
  • Product
  • Who We Help
    • Sales & RevOps
    • Support & CX
    • Marketing
    • Executives
    • Operations
  • Client Services
  • Company
    • About
    • Careers
    • Blog
    • Security & Privacy
    • Partners
    • Contact Us
    • FAQs
  • Case Studies
Demo

 

 

Privacy policy

At harpin AI, we take your privacy seriously. Please read this Privacy Policy to learn how we treat your
personal data. By using or accessing our Services in any manner, you acknowledge that you accept the
practices and policies outlined below, and you hereby consent that we will collect, use and share your
information as described in this Privacy Policy.

Remember that your use of harpin AI Services is at all times subject to our Terms of Use, which
incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions
given to them in the Terms of Use.

You may print a copy of this Privacy Policy by clicking here.


Table of Contents

  • 1. Purpose
  • 2. Scope
  • 3. Definitions
  • 4. Summary
  • 5. When You Visit Our Website or Contact Us
    • 5.1 What we collect
    • 5.2 Why we use it, and our legal basis
    • 5.3 Cookies and similar technologies
    • 5.4 The tools we use on the website
    • 5.5 Who receives website data
    • 5.6 Your choices
    • 5.7 Marketing email
    • 5.8 How long we keep website data
  • 6. When You Use Software or Services We Provide to a Customer
    • 6.1 How this works
    • 6.2 Fluent
    • 6.3 Subprocessors
    • 6.4 How long we keep customer data, and deletion
  • 7. Security
  • 8. Personal Data of Children
  • 9. Your Privacy Rights
    • 9.1 California
    • 9.2 Oregon
    • 9.3 Other states
    • 9.4 How to submit a request
    • 9.5 Response times, agents and appeals
    • 9.6 The European Economic Area, the United Kingdom and Switzerland
  • 10. Legal Requests
  • 11. Where We Store Data
  • 12. Changes to This Policy
  • 13. Contact Information

1. Purpose

This Privacy Policy explains how Ponchos & Huaraches, Inc., doing business as harpin AI (“harpin AI”, “we”, “us”), collects, uses, shares and protects personal data. It is the notice harpin AI publishes to meet its transparency obligations under applicable data privacy laws, and it is the privacy policy linked from harpin AI’s software listings.

This document is the source of record for the text published at https://harpin.ai/privacy-policy/. The published page is a copy of an approved version of this document and is not edited independently of it.


2. Scope

Privacy laws separate the organization that decides why and how personal data is used from the organization that processes personal data on that organization’s instructions. harpin AI acts in both roles, and this policy covers both.

Section 5 applies when harpin AI decides. This covers visitors to harpin.ai, people who complete a form or send us an email, and people who receive our marketing communications.

Section 6 applies when a customer decides. Our customers deploy our software and services, including identity resolution, customer analytics and call assistance, to their own employees and customers. In those cases the customer determines the purposes and means of processing, and harpin AI acts on the customer’s documented instructions under a written agreement. Where your data reached us that way, the customer is your first point of contact, and the customer’s own privacy notice describes its practices.

Section 6.1 also covers a limited set of decisions harpin AI makes itself about people who use our software, because the customer does not make them: creating and securing user accounts, keeping the software running, monitoring for security problems, and diagnosing errors.

This policy does not cover the practices of organizations harpin AI does not own or control.


3. Definitions

Personal data means information that identifies or relates to an identifiable person, including information referred to as “personal information” or “personally identifiable information” under applicable data privacy laws.

Sensitive personal information means the categories given that name under the California Consumer Privacy Act, including government identifiers, financial account numbers, precise geolocation, and health information.

Controller (or “business”) means the organization that determines the purposes and means of processing personal data.

Processor (or “service provider”) means an organization that processes personal data on a controller’s documented instructions.

Customer means an organization that has entered an agreement with harpin AI for its software or services.

Fluent means harpin AI’s call-assistance software, comprising Fluent Assist, a Google Chrome extension, and Fluent Edge, a desktop application.


4. Summary

On our website we use analytics and advertising tools, listed by name in section 5.4, and a consent banner lets you decline the ones that are not essential.

We do not exchange personal data for money. Whether some of the advertising tools on our website count as a “sale” or “sharing” under state law is addressed in section 5.5, and you can opt out either way.

Inside customer deployments we act on the customer’s instructions and keep data for the term of our agreement with the customer.

Fluent transcribes speech on the agent’s workstation and removes spoken numbers, including payment card numbers, before anything is displayed or sent. It does not record calls or upload audio in its shipped configuration. Automatic removal is not perfect, and section 6.2 says where it falls short and lists everything Fluent handles.

You can reach us at privacy@harpin.ai for any request or question.


5. When You Visit Our Website or Contact Us

5.1 What we collect
Category Examples Where it comes from
Contact details Name, work email, company, phone number, the topic you selected, and what you write in the message box You, through our contact form or by email
Correspondence The content of emails, meeting requests and other messages you send us, and our replies You
Device and connection data IP address, browser type, operating system, screen size, referring page, the pages you view and how long you stay, approximate location derived from your IP address Your browser, collected automatically by the tools in section 5.4
Identifiers set by our tools Cookie identifiers and similar identifiers stored on your device by the tools in section 5.4 Those tools, subject to your consent choices
Business contact data Name, job title, company, work email address and work phone number of people at businesses we may wish to contact Third-party providers of business contact data used by our sales team

We do not collect sensitive personal information from website visitors, and we ask you not to send it to us through the contact form.

5.2 Why we use it, and our legal basis
Purpose Data used Legal basis for visitors in the EU and UK
Answering your enquiry and arranging demos or meetings Contact details, correspondence Steps you asked us to take before entering a contract; our legitimate interest in responding to you
Running, securing and improving the website Device and connection data, essential identifiers Our legitimate interest in a working, secure website
Understanding how visitors use the site Device and connection data, analytics identifiers Your consent
Advertising our services and measuring campaigns Device and connection data, advertising identifiers Your consent
Sending marketing email Contact details Your consent, or our legitimate interest where the law allows business-to-business email without consent; every message carries an unsubscribe link
Contacting businesses that may be interested in our services Business contact data Our legitimate interest in business-to-business sales; every message carries an unsubscribe link
Meeting legal obligations, resolving disputes, enforcing our terms Any of the above as needed Legal obligation; our legitimate interest in protecting our rights

We do not use website data for automated decisions that have legal or similarly significant effects on you.

5.3 Cookies and similar technologies

Our website uses cookies, local storage, pixels and scripts (“cookies”) to run the site, remember your choices, measure usage and support advertising. We group them as follows.

Essential. Needed for the site to work and to protect it, including security and caching. These do not require consent.

Analytics. Tell us how visitors use the site.

Advertising. Measure our advertising and let us show relevant advertising on other services.

5.4 The tools we use on the website
Tool Provider What it does on harpin.ai Category Provider’s privacy information
Google Analytics 4 Google LLC Measures visits and page usage Analytics Google Privacy Policy; opt out with the Google Analytics opt-out add-on
Google Ads Google LLC Measures advertising conversions and supports remarketing Advertising Google Ads privacy and technologies; manage at Google Ads settings
Google Tag Manager Google LLC Loads the tools in the categories you accept Loader Google Privacy Policy
HubSpot HubSpot, Inc. Runs our demo-request and lead forms, links those submissions to a contact record, and sends our marketing email Marketing HubSpot Privacy Policy
Cloudflare Cloudflare, Inc. Protects the site from automated abuse Essential Cloudflare Privacy Policy
NitroPack NitroPack Ltd. Speeds up page loading Essential NitroPack Privacy Policy
Gravity Forms Rocketgenius, Inc. Operates the contact and careers forms on our website. Submissions are stored on our website and delivered by email to the harpin AI staff responsible for responding Essential Runs on our own site

We update this table when we add or remove a tool. The tools above reflect our website configuration as of 16 September 2026.

5.5 Who receives website data

Service providers that process data for us under contract: our hosting, caching, security and email providers, HubSpot, and Google for analytics and tag management.

Advertising providers named in section 5.4. These providers may use the data they collect for their own purposes as described in their privacy policies. Under the California Consumer Privacy Act, disclosing identifiers to advertising providers for cross-context behavioral advertising can count as “sharing”, and disclosing data to a provider that uses it for its own purposes can count as a “sale”, even when no money changes hands. You can opt out under section 5.6 regardless of how these disclosures are classified.

Authorities and other parties when the law requires it, as described in section 10.

A successor if we merge, are acquired, or transfer our business. We will make reasonable efforts to tell you before your data becomes subject to a different privacy policy.

Aggregated or de-identified data, which does not identify you, may be used and shared for any lawful purpose. We do not try to re-identify it.

We do not exchange personal data for money.

5.6 Your choices
  • Consent banner. When you first visit, a banner lets you accept or decline analytics and advertising cookies. Non-essential tools do not run until you accept. You can change or withdraw your choice at any time through the “Revoke consents” link in the page footer.
  • Do Not Sell or Share My Personal Information. Use the link of that name in the page footer to opt out of the disclosures described in section 5.5. The link opens the same banner, so opting out and declining non-essential cookies are the same action.
  • Global Privacy Control. Our website does not currently respond to the Global Privacy Control browser signal. To opt out of sale and sharing, use the “Do Not Sell or Share My Personal Information” link in the page footer.
  • Do Not Track. Browsers can send a “Do Not Track” signal. There is no common standard for it, and our website does not change its behavior in response to it. Use the choices above instead.
  • Provider controls. Each provider in section 5.4 offers its own opt-out, linked in the table.
  • Browser settings. You can block or delete cookies in your browser. Blocking essential cookies may stop parts of the site from working.
5.7 Marketing email

If you give us your work email at an event, through a form, or in correspondence, or if we obtain your business contact details from a third-party provider of business contact data, we may send you information about our products and events. Every marketing email includes an unsubscribe link and our postal address, and we honor unsubscribe requests promptly and in any event within ten business days. Unsubscribing does not stop transactional or account emails.

Business contact data obtained from third-party providers is used only for our own sales and marketing outreach. It is not loaded into the software or services we provide to customers, and it is never combined with data we process for a customer, including Fluent.

5.8 How long we keep website data

Contact details and correspondence are kept for as long as we have an active conversation or business relationship with you or your company, and afterwards only as long as we need them to keep records of that relationship or to meet legal obligations. You can ask us to delete them at any time under section 9.

Analytics and advertising data are kept for the retention period configured in each tool, after which the provider deletes or aggregates it.

Aggregated statistics that do not identify you may be kept indefinitely.


6. When You Use Software or Services We Provide to a Customer

6.1 How this works

Our customers use our platform and applications to resolve customer identities, analyze customer interactions, and assist their agents during calls. The customer decides what data goes in, who can see it, and how long it is kept, and we process it on the customer’s documented instructions under our agreement with that customer, which includes data-protection terms. If you are a customer’s employee or customer and want to exercise a right over data in a customer’s deployment, contact the customer; we will help the customer respond.

A limited set of decisions are ours, because they are part of running the software rather than part of the customer’s use of it.

Accounts and sign-in. We create and secure your user account, issue sign-in tokens, and record sign-in events. We keep account records while your account exists and for a short period afterwards so the customer can reinstate it.

Security monitoring. We log access to our systems and investigate suspicious activity. Security logs are kept for the period our security policy sets and are then deleted.

Diagnostics. We collect error reports and limited usage events so we can fix problems. Error reports are kept for the retention period configured in our error-monitoring service, currently 90 days.

For these purposes we use your name, work email, role, the customer you belong to, and technical event data. Our legal basis in the EU and UK is our legitimate interest in providing secure, working software, and our contract with the customer. You can contact us directly about these at privacy@harpin.ai.

6.2 Fluent

Fluent is call-assistance software that a customer deploys to its call-center agents. It has two parts on the agent’s computer: Fluent Assist, a Google Chrome extension that opens in Chrome’s side panel, and Fluent Edge, a desktop application for Windows and macOS that captures and transcribes call audio. Fluent Assist cannot hear anything without Fluent Edge. Your employer or the customer that deploys Fluent decides which features are turned on.

What Fluent handles
What Details Who receives it
Call detection In its standard configuration, Fluent Edge listens to your microphone and your computer’s audio the whole time it is running, so that it can detect automatically when a call starts and ends without you clicking anything. Audio outside a detected call is used only for that decision and is held in memory; a few seconds of it are kept in memory so the opening words of a call are not lost. Your employer can instead configure Fluent to start only when you tell it to. No one; this audio is not saved or sent
Authentication information Sign-in tokens issued by our identity service after you sign in, either with a username and password held in our identity service or through your organization’s identity provider. The desktop app stores them in your operating system’s credential store; the extension keeps them in browser session storage, which is cleared when the browser closes. If you use Fluent alongside Salesforce, the extension reads your Salesforce session cookie and uses it only to ask Salesforce which user is signed in; the cookie itself is not sent to us. Our identity service; Salesforce’s own user-identity service
Your account identity Your name, work email, role and the customer organization you belong to; if Salesforce is in use, your Salesforce user and organization identifiers, which may be associated with your call records. A supervisor or administrator at your employer may be able to view Fluent as you. Our cloud service; your employer’s supervisors and administrators as configured by the customer
Call content Speech on the call is transcribed into text on your workstation. Before any text is shown to you or sent anywhere, Fluent removes spoken numbers: every run of three or more digits is replaced unless it is recognized as ordinary business content such as a date or a booking reference, and payment card numbers, Social Security numbers and card security codes are removed whenever they are detected. Automatic removal is not perfect: digits broken into short fragments, or the cued categories spoken in a language other than English, may not be recognized. Names and email addresses spoken on the call are not removed and may appear in the transcript. During the call, a redacted window of recent transcript is sent to our cloud service about every fifteen seconds by default, and your employer can configure a different interval. At the end of the call, the redacted transcript, the wrap-up, the disposition, the guidance shown and the actions you took are saved. Our cloud service; the AI providers below, to generate guidance, search results and wrap-ups; your employer as configured by the customer
Customer details attached to a call When a call is matched to a customer record, the finalized call carries that customer’s details, which can include names, phone numbers, email addresses, postal addresses, date of birth, account identifier and linking keys. This is the customer’s data and we process it on the customer’s instructions. Our cloud service; your employer
Tone and sentiment indicators Our AI models derive indicators from the transcript text, such as sentiment, an empathy cue, the caller’s intent and risk flags, for each speaker turn, including your own, and an overall sentiment saved with the call. These are shown to you as guidance. Our cloud service; your employer as configured by the customer
Customer records you look up When you search for a customer through Fluent, it retrieves that customer’s profile, transactions, events, loyalty program details and scores from the harpin platform your employer has connected. This is the customer’s data and we process it on the customer’s instructions. Our cloud service; you
Your work product Wrap-up summaries you review and edit, notes, dispositions, and actions you log Our cloud service; your employer as configured by the customer
Activity logging, if your employer turns it on Off by default. Where a customer turns it on and configures a list of applications, Fluent records which of those applications and screens you used during a call and what you did there, and sends that with the finalized call. Our cloud service; your employer
Product diagnostics The extension sends error reports and a sample of usage events, for example that a search was run or a guide step was completed, to our error-monitoring provider. These carry a user identifier and your customer’s identifier, and no call content. An error report also carries your IP address and a short trail of the requests the panel made just before the error, which can include the identifier of a customer record you had open. The desktop app sends no usage events. Sentry, our error-monitoring provider
Browser activity The extension checks the address of the tab you are viewing to detect a supported CRM page. Addresses are evaluated on your computer and are not sent to us or stored. No one
What Fluent does not do
  • It does not record calls and does not upload call audio. Audio is processed in memory on your workstation and is not retained in the shipped configuration.
  • It does not keep a transcript file on your computer unless your employer turns on diagnostic logging.
  • It does not read or change the content of the web pages you visit, and it does not capture your screen, keystrokes or clipboard. It uses Salesforce’s own interface only to look up which Salesforce user is signed in.
  • It does not use your data for advertising, and we do not sell it.
  • It does not make automated decisions about you. The indicators and guidance above are advisory, and how your employer uses Fluent’s output in managing its workforce is the employer’s decision.
Where the data goes

Text and events travel from the extension to the desktop application on your computer, then over encrypted connections to our cloud service, hosted on Amazon Web Services. To generate guidance, search results and wrap-ups, our service sends the redacted transcript text to OpenAI, through a gateway we operate, with Amazon Bedrock as a fallback provider. Neither provider uses this text to train its models, and we do not use it to train any model of our own. This text may be held for up to thirty days (or longer if the provider determines it is needed to detect misuse of its service), and is deleted after that period. The extension sends error reports to Sentry. No other third party receives Fluent data unless your employer connects one.

Chrome Web Store statement

Fluent Assist has a single purpose: to help call-center agents during customer calls with a live transcript, guidance and call wrap-up. It collects only the data needed for that purpose, and our use of that data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. If we change how Fluent Assist handles your data, we will record the change in this policy’s revision history and tell your organization’s administrator before it takes effect.

6.3 Subprocessors

The third parties that process customer data on our behalf are listed at https://harpin.ai/security-privacy/. For Fluent they are Amazon Web Services, OpenAI and Sentry. Across our other software and services we also use Anthropic PBC and Google. Customers with a data-processing agreement are notified of changes as that agreement provides.

6.4 How long we keep customer data, and deletion

We keep data processed for a customer for the term of our agreement with that customer, or for the shorter period the customer instructs, and we handle it at the end of the agreement as the agreement provides. Deletion of data inside a customer’s deployment is directed by the customer under that agreement; if you are a customer’s employee or customer, contact the customer.


7. Security

We encrypt data in transit using TLS 1.2 or higher and at rest using AES-256. Access to production systems is limited to personnel who need it for their role, requires multi-factor authentication, and is logged. An independent auditor examined our controls against the SOC 2 Security criteria (Type II); customers and prospects can request the report under a non-disclosure agreement. If a security incident affects a customer’s data, we notify that customer as our agreement with them requires. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You can report a security concern to security@harpin.ai.


8. Personal Data of Children

Our website and services are for businesses and their staff. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, email privacy@harpin.ai and we will delete it.


9. Your Privacy Rights

Your rights depend on where you live and on whether harpin AI decided how your data was used (sections 5 and 6.1) or a customer did (section 6). Where a customer decided, please contact the customer; we will help the customer respond to you.

9.1 California

If you are a California resident, you have the right to know the categories and specific pieces of personal data we have collected about you, the sources, our purposes, and the categories of third parties we disclosed it to. Sections 5.1 to 5.5 describe our current practices; the tools listed there reflect our configuration as of 16 September 2026.

You have the right to delete personal data we collected from you, subject to legal exceptions, and the right to correct inaccurate personal data.

You have the right to opt out of sale or sharing, using the “Do Not Sell or Share My Personal Information” footer link described in section 5.6.

You have the right to limit the use of sensitive personal information. We do not collect sensitive personal information from website visitors, so there is nothing to limit.

You have the right not to be discriminated against for exercising these rights.

Under Civil Code sections 1798.83 to 1798.84 you may ask which third parties received your personal data for their own direct marketing. Email privacy@harpin.ai.

9.2 Oregon

If you are an Oregon resident, you have the right to confirm whether we process your personal data, to access it, to correct it, to delete it, to receive a copy in a portable format, and to opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. We do not profile website visitors in that way. You may also ask for a list of the specific third parties to which we have disclosed your personal data. Email privacy@harpin.ai.

9.3 Other states

Many other states with comprehensive privacy laws, including without limitation Colorado, Connecticut, Nevada, Virginia and Texas, may have rights of access, correction, deletion, portability, and opt-out from targeted advertising, sale and profiling. If you reside outside California or Oregon, check your state’s policies regarding data privacy rights and/or send an email to privacy@harpin.ai; we will apply the data privacy rights of your state to your requests.

9.4 How to submit a request

Email privacy@harpin.ai with your name, the email address you used with us, the state or country you live in, and the right you want to exercise. We verify requests by matching the name and email address you give us against our records and, if needed, by replying to that email address. We do not ask for more than we need to verify you. You do not need an account.

9.5 Response times, agents and appeals

We respond within 45 days of a verified request, and we tell you if we need up to 45 more days. We do not charge for requests unless they are excessive or repetitive, and we tell you first. You may use an authorized agent; we ask for the agent’s written permission from you and may confirm the request with you directly. If we deny a request, you may appeal by replying to our response; we answer appeals within the period your state’s law sets.

9.6 The European Economic Area, the United Kingdom and Switzerland

Where we decide how your data is used, you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting processing that already happened. You can also lodge a complaint with your data protection authority. Section 5.2 gives our legal basis for each purpose. Your data is stored in the United States; section 11 describes the safeguards.

Our representative in the EU is Instant EU GDPR Representative Limited (GDPR Local), Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland, and our representative in the UK is GDPR Local Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton, BN1 1EB, England; both can be reached at contact@gdprlocal.com or through privacy@harpin.ai.

Where a customer decides, the customer is the controller and harpin AI is its processor.


10. Legal Requests

We disclose personal data in response to subpoenas, court orders, warrants and similar legal demands when we determine the demand is valid, and we disclose only what the demand specifies. Where we are permitted and it is practical, we tell the affected customer before we disclose its data.


11. Where We Store Data

Our website data and our production services run in the United States, on Amazon Web Services in the US West (Oregon) region. Where a customer’s agreement provides for a deployment in another region, that agreement says so.

If you are outside the United States, your data is transferred to and processed in the United States, where privacy laws may differ from those of your country. For data from the EEA, UK and Switzerland we rely on the Standard Contractual Clauses adopted by the European Commission, with the UK International Data Transfer Addendum and the Swiss adjustments where they apply, available on request from privacy@harpin.ai.


12. Changes to This Policy

We update this policy when our practices, tools or the law change. Each version carries a version number, an effective date and a last-revision date.

For material changes we post a notice on our website before the change takes effect. For software installed on your computer we tell your organization’s administrator, and tell you in the product where the product supports it.

Continuing to use the website or software after a change takes effect means the new version applies.


13. Contact Information

Privacy questions and requests: privacy@harpin.ai

Security concerns: security@harpin.ai

Data Protection Officer: reachable at privacy@harpin.ai

Post: Data Protection Officer, harpin AI, 2900 NW Clearwater Dr. #200, Bend, OR 97703, United States

 

harpin.AI harpin.AI
  • LinkedIn
  • Terms of Use
  • Privacy Policy
  • Change privacy settings
  • Privacy settings history
  • Revoke consents

© harpin AI 2026

  • Product
  • Who We Help
    • Sales & RevOps
    • Support & CX
    • Marketing
    • Executives
    • Operations
  • Client Services
  • Company
    • About
    • Careers
    • Blog
    • Case Studies
    • Security & Privacy
    • Partners
    • Contact Us
    • FAQs